当前位置:网站首页>F5 big IP Icontrol rest command execution (cve-2022-1388)
F5 big IP Icontrol rest command execution (cve-2022-1388)
2022-06-29 10:19:00 【Qianli ZLP】
One 、 Vulnerability description
2022 year 5 month 6 Japan ,F5 The official website publishes safety announcements , Disclosure F5 BIG-IP There is a Remote Code Execution Vulnerability (CVE-2022-1388). The flaw lies in iControl REST In the component , The vulnerability allows attackers who define authentication to pass BIG-IP Manage the interface and yourself IP The address of iControl REST API Interface for network access , As a result, arbitrary system commands can be executed on the target host 、 Create or delete files or disable BIG-IP Service on .
Components :F5 BIG-IP iControl REST
Hole type : Authentication bypasses
influence : Command execution
sketch : This vulnerability allows an unauthenticated attacker to pass through the management port or self body ip The address of BIG-IP System access , To perform duties Meaning system commands , Create or delete files and disable BIG-IP Service on .
Two 、 scope
BIG-IP 16.x: 16.1.0 - 16.1.2
BIG-IP 15.x: 15.1.0 - 15.1.5
边栏推荐
猜你喜欢
随机推荐
Codeforces Round #652 (Div. 2)
2019.10.30 learning summary
QGIS mapping
Codeforces Round #659 (Div. 2)
另类实现 ScrollView 下拉头部放大
2019.10.30学习总结
Sixteen system counter and flow lamp
This open source project is super wow, and handwritten photos are generated Online
nacos注册中心集群
Ce projet Open source est super wow, des photos manuscrites sont générées en ligne
Shanke's C language 2018 exercise (Telecom)
2019.10.16 training summary
TLAB of JVM
Sublime Text3 set to run your own makefile
时变和非时变
Nacos environmental isolation
520 diamond Championship 2021
Simulation problem of two stacks
Setinterval, setTimeout and requestanimationframe
同花顺炒股软件可靠吗,安全吗?







